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Abstract 



C^l \ We study the problem of designing group-strategyproof cost-sharing mechanisms. The 

players report their bids for getting serviced and the mechanism decides which players are 
going to be serviced and how much each one of them is going to pay. We determine three 
f-H ■ conditions: Fence Monotonicity, Stability of the allocation and Validity of the tie-breaking 

| rule that are necessary and sufficient for group-strategyproofness, regardless of the cost 

function. Fence Monotonicity puts restrictions only on the payments of the mechanism 
q | and stability only on the allocation. Consequently Fence Monotonicity characterizes 

group-strategyproof cost-sharing schemes. Finally, we use our results to prove that there 
exist families of cost functions, where any group-strategyproof mechanism has unbounded 
approximation ratio. 

T— I ' 

o 

C\ ■ 1 Introduction 

o 
o 



Algorithmic Mechanism Design |15| is a field of Game Theory, that tries to construct algo- 
rithms for allocating resources, that give to the players incentives to report their true interest 
in receiving a good, a service, or in participating in a given collective activity. The pivotal 
constraint when designing a mechanism for any problem is that it is truthful. Truthfulness 
also known as strategy-proofness or incentive compatibility requires that no player can strictly 
improve her utility by lying, when the values of the other players are fixed. In many settings 
this single requirement for an algorithm to be truthful restricts the repertoire of possible 
algorithms dramatically [9J. 

In settings where the repertoire of possible algorithms is not restricted too much by truth- 
fulness, like for example in Cost-sharing problems it is desirable to construct mechanism that 
are also resistant to manipulation by groups of players. Group-strategyproofness naturally 
generalizes truthfulness by requiring that no group of players can improve their utility by 
lying, when the values of the other players are fixed. To be more precise there should not 
exist any group of players who can change their bids in a way that every member of the 
coalition is at least as happy as in the truthful scenario, and at least one person is happier, 
for fixed values of the players that do not belong to the coalition. 
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In this paper we study the following problem: We want to determine a set of n cus- 
tomers/players, who are going to receive a service. Each player reports her willingness to pay 
for getting serviced and the mechanism decides which players are going to be serviced and the 
price that each one of them will pay, that is we consider direct revelation mechanisms. We 
want to characterize all possible mechanisms that satisfy group-strategyproofness, we want 
to find some necessary and sufficient conditions for a mechanism to be strategyproof and also 
to determine the corresponding payments. 

We provide a complete characterization of group-strategyproof mechanisms and cost- 
sharing schemes, closing a open question posed by Immorlica, Mahdian and Mirrokni [5j 
[T7] by extending the condition of Semi-cross-montonicity they identified in [5] to a new 
condition, which we call Fence Monotonicity and by defining Fencing Mechanisms, a new 
general framework for designing group-strategyproof mechanisms. 

Our results are of special importance for a very important problem, the Cost-Sharing 
Problem, whose study was initiated in [13], where we additionally have a cost function C, 
such that for each subset of players S the cost for providing service to all the players in S 
is C(S), however the strength of our results is that they apply for any cost function, since 
throughout our proof we do not make any assumptions at all about this cost function. We 
believe that our work here can be the starting point for constructing new interesting classes 
of mechanisms for specific cost-sharing problems. 

Recently Mehta, Roughgarden and Sundararajan [12] proposed the notion of weak group- 
strategy-proofness, that relaxes group-strategyproofness. It regards a formation of a coalition, 
as successful, when each player who participates in the coalition strictly increases her personal 
utility. They also introduce acyclic mechanisms, a general framework for designing weakly 
group-strategyproof mechanisms, however the question of determining all possible weakly 
group-strategyproof mechanisms is an important question that remains open. Another alter- 
native notion that is slightly stronger than weak-group-strategyproofness and weaker than 
group-strategyproofness was proposed by Bleischwitz, Monien and Schoppmann in pQ. 

2 Our results and related work 

The design of group-strategyproof mechanisms for cost-sharing was first discussed by Moulin 
and Shenker [13} [Tl] . Moulin defined a condition on the payments called cross- monotonicity, 
which states that the payment of a serviced player should decrease as the set of serviced 
players grows. Any mechanism whose payments satisfy cross-monotonicity can be easily 
turned to a simple mechanism called after Moulin. A Moulin mechanism first checks if all 
players can be serviced with positive utility and gradually diminishes the set of players that 
are candidates to be serviced, by throwing away at each step a player that cannot pay to 
get serviced (and who because of cross-monotonicity also cannot pay in any smaller set of 
serviced players). In fact if the cost function is sub-modular and 1-budget balanced then 
the only possible group-strategyproof mechanisms are Moulin mechanisms [13] ■ The great 
majority of cost-sharing mechanisms proposed are Moulin mechanisms [6]. I18 |, [TO ], . However 
recent results showed that for several important cost-sharing games Moulin mechanisms can 
only achieve a very bad budget balance factor [21 [20], [11]. Another direction proposed 
by Moulin and rediscovered in [31 [7] resulting to weakly-group-strategyproof mechanisms are 
Incremental mechanisms where after ordering the players appropriately you ask them one by 
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one if their bid is greater than an appropriate cost-share. Some alternative, very interesting 
and much more complicated in their description mechanisms that are group-strategyproof 
but not Moulin have been proposed in [5j [19], however these do not exhaust the class of 
group-strategyproof mechanisms. 

In this work we introduce Fencing Mechanisms, a new general framework for designing 
group-strategyproof mechanisms, that generalizes Moulin mechanisms |13| . Unfortunately for 
the general case we do not know if there exists a polynomial-time algorithm that implements 
these mechanisms. 

Finding a complete characterization of the cost-sharing schemes that give rise to a group- 
strategyproof mechanism was a question that was posed in [5l [17] . The same question was 
posed in [12] for weak group-strategyproof cost-sharing schemes and still remains open. Many 
interesting results arose in the attempt to find such a characterization |19t [7] . In contrast to 
previous characterization attempts that characterized mechanisms satisfying some additional 
boundary constraints 0(7] our characterization is complete and succinct. The only complete 
characterization that was known was for the case of two players [191 [7]. It remains open 
how can our characterization help for constructing new efficient mechanisms for specific cost- 
sharing problems or for obtaining lower bounds and we belive that it can significantly enrich 
the repertoire of mechanisms with good approximation guarantees for specific problems. 

In the notion of group-strategyproofness it is important to understand that ties play a 
very important role. This is in contrast to mechanisms that are only required to satisfy 
strategyproofness, where ties can be in most cases broken arbitrarily (see for example |16j). 
An intuitive way to understand this is that a mechanism designer of a group-strategyproof 
mechanism expects a player to tell a lie in order to help the other players increase their 
utility, even when she would not gain any profit for herself. This player is at a tie but decides 
strategically if she should lie or not. Consequently a characterization that assumes a priori 
a tie-breaking rule, and thus greatly restricts the repertoire of possible mechanisms, like the 
one in [5j [8] might be useful for specific problems and easier in its statement, but can never 
capture the very notion group-strategyproofness. 

We determine three conditions: Fence Monotonicity, Stability of the allocation and 
Validity of the tie-breaking rule that are necessary and sufficient for group-strategyproof- 
ness, regardless of the cost function and without any additional constraints (like tie-breaking 
rules used in [5j [7]). Fence Monotonicity concerns only the payments of the mechanism, 
while Stability and Validity of the tie-breaking rule, only the allocation. Consequently Fence 
Monotonicity characterizes cross-monotonic cost-sharing schemes. Having only the payments 
of a group-strategyproof mechanism is however not enough to determine its allocation. The 
allocation of a mechanism based on a cost-sharing scheme that satisfies Fence Monotonicity, 
should additional satisfy a condition we call Stability. Managing to separate the payments 
from the allocation part of the mechanism and avoiding to add any additional restrictions in 
the characterization we propose are undoubtedly its great virtues. 

Our proofs are involved and based on set-theoretic arguments and the repeated use of 
induction. The main difficulty of our work was to identify some necessary and sufficient 
conditions for group-strategyproof payments that are also succinct to describe and add to our 
understanding of the notion of group-strategyproofness. In proving that Fence Monotonicity 
is a necessary condition for group-strategyproofness we first have to prove Lemmas that 
also reveal interesting properties of the allocation part of the mechanism. A novel tool that 
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we introduce is the harm relation that generalizes the notion of negative elements defined 
in [5]. Proving that Fencing Mechanisms, i.e. mechanisms whose payments satisfy Fence 
Monotonicity and whose allocation satisfies Stability and Validity of the tie-breaking rule, 
are group-strategyproof turns out to be rather complicated. 

3 Defining the model 

3.1 The Mechanism 

Suppose that A = {1, 2, . . . , n} is a set of players interested in receiving a service. Each of 
the players has a private type Vi, which is her valuation for receiving the service. 

Definition 1. A cost sharing mechanism (0,p) consists of a pair of functions, O : M™ — > 2 A 
that associates with each bid vector b the set of serviced players and p : M n — > M. n that 
associates with each bid vector b a vector p(b) = p(b±, . . . , b n ), where the i-th coordinate is 
the payment of player i. 

Each player wants to maximize her utility, which assuming quasi-linear utilities is ViCii — 
Pi(b) where dj = 1 if i G 0(b) and aj = if i 0{b). 

As is common in the literature and in order not to come up with useless mechanisms, we 
concentrate on mechanisms that satisfy the following very simple conditions |13j : 

• Voluntary Participation (VP): A player that is not serviced is not charged (i ^ 0(b) => 
Pi (b) = 0) and a serviced player is never charged more than his bid (i G 0(b) =^> Pi(b) < 
bi). 

• No Positive Transfer (NPT): The payment of each player i is positive (pi{b) > for all 
i). 

• Consumer Sovereignty ( CS): For each player i there exists a value i* £ I such that if 
he bids b* then it is guaranteed that i will receive the service no matter what the other 
players bid. 

Obviously, VP implies that if an player is truthful, then her utility is lower bounded by 
zero. Moreover, VP and NPT imply that if a player announces a negative amount, then she 
will not be included in the outcome. While, negative bids are not realistic, the latter may be 
used to model, the denial of revealing any information to the mechanism. Finally, notice that 
the crucial value b*, in the definition of CS is independent of the bid vector. Thus, this value 
has to be greater or equal to any possible payment this player is charged, i.e. b* > Pi(b), for 
all b G W 1 . 

Definition 2. We say that a cost-sharing mechanism is group-strategyproof (GSP) if and 
only if the following holds: For every two valuation vectors v, v' and every S'Ci, sat isfying 
Vi = v[ for all i G S, one of the following is true: 

(a) There is some i G S, such that v[ai — Pi(v') < ViOi — Pi(v), or 

(b) for all i G S, it holds that Via[ — Pi(v') = ViQi — Pi(v). 
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In other words, a GSP mechanism does not allow successful coalitions of the players, i.e. 
that a group of a players announces a false value, instead of their true valuations and moreover 
no "liar" sacrifices her utility, while at least one player (not necessarily a liar) strictly profits 
after the manipulation. 

Definition 3. A cost-sharing scheme is a function £ : A x 2 A -> R+ U {0}, such that, for 
every S C A and every i £ S we have 5) = 0. 

You can think of S 1 ) as the payment of player i if the serviced set is S. In fact it can 
be shown that in any group-strategyproof mechanism for our setting the payment of a player 
depends only on the allocation of the mechanism and not directly on the bids of the players. 
In this sense we do not restrict the mechanism in any way by assuming that the payments 
are given by a cost-sharing scheme £. 

3.2 The cost function and budget balance 

The cost of providing service service is given by a cost function C : 2* 4 — > M + U {0}, where 
C(S) specifies the cost of providing service to all players in S. 

A desirable property of cost-sharing mechanisms is budget balance. We say that a 
mechanism is a-budget balanced, where < a < 1, if for all bid vectors b it holds, that 
a-C{0{b)) <Ziest(hS) <C(0(b)). 

We chose to define the cost function last in order to stress that our results are completely 
independent of the cost function and apply to any cost-sharing problem. 

3.3 Cross- and Semi-cross-monotonicity 

We say that a cost-sharing scheme is cross-monotonic [2] if £(i,S) > £(£, T) for every 
ScTCi and every player i G S. 

In the attempt to provide a characterization of GSP cost-sharing schemes Immorlica Mah- 
dian and Mirrokni [5] provided a partial characterization and identified semi-cross monotonic- 
ity an important condition that should be satisfied by any GSP cost-sharing scheme. A cost 
sharing scheme £ is semi-cross monotonic if for every S C A an player i £ S all j € S \ {i} : 
either 5 \ {i}) < S) or S \ {i}) > S). Notice that every cross monotonic cost 
sharing scheme is also semi-cross monotonic, since the second or condition is always true, 
however the converse does not hold. 

As we later show in Proposition [T] (a) Semi-cross-monotonicity can be almost directly 
derived from the condition of Fence Monotonicity we define in this work and more specifically 
from part (a) of Fence Monotonicity. 

4 Our Characterization 
4.1 Fence Monotonicity 

Fence Monotonicity considers each time a restriction of the mechanism that can only output 
as the serviced set, subsets of U that contain all players in L. To be more formal consider 
all possible subsets of the players L, U such that L C U C A- Fixing a pair L C U Fence 
Monotonicity considers only sets of players S with L C S C U. 
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Let L, U) be the minimum payment of player i, for getting serviced when the output 
of the mechanism is between L and U, i.e. £*(i,L,U) := mi^{LCSCii,ieS} 

Definition 4 (Fence Monotonicity) . We will say that a cost-sharing scheme satisfies Fence 
Monotonicity if it satisfies the following three conditions: 

(a) There exists at least one set S with L C 5 C U, such that for all % G i? we have 

a(i,s)=z*(i,L,u). 

(b) For each player i £ U \ L there exists at least one set Si, with L C Si C [/ ', such that 
for all j £ Si\ L, we have Si) = L, f7). 

(Note that i £ Si \ L and thus £(i,Si) = £*(i,L,U). Also note that we might have 
Sj / Sj for i ^ j.) 

(c) If there exists a set C C U, such that for some player i we have i G C and C) < 

f7) (obviously L <^-C), then there exists at least one set T 7^ 0, with T C L\C 
such that for all j G T, ^(j, CUT) = L, [7). 

The first condition says that if we necessarily have to service the players in L, there ex- 
ists a superset S of L, such that if all players in S such that the serviced players achieve 
their lowest possible (non-zero) payment £*(i,L,U). As we show in Proposition a), this 
condition generalizes the condition of semi-cross-monotonicity, which was identified as nec- 
essary for group-strategyproofness in [5] and in this sense our work completes the partial 
characterization obtained in [5]. 

The second condition says then for each player % G U \ L there exists an outcome Si, 
such that i £ Si, and such that all players in Si \ L are served with their lowest possible 
payment. Loosely speaking this gives a way to enlarge L by adding to it more players in a 
way that is optimal for the players that we add. Note that the cost of the players already 
in L might however increase, which in fact relaxes cross-monotonicity, in the sense that if 
we further restrict the second condition to hold for every j G Si, then the underlying cost 
sharing schemes are cross-monotonic. 

The third condition compares the minimum possible non-zero payment of each player in 
this restriction of the mechanism, with his minimum possible non-zero payment when the 
outcome can be any subset of U (i.e. the the output should not necessarily contain the 
players in L). If the first payment is bigger then this means that some of the players in L are 
responsible for this higher payment and "harm" the player. Very loosely speaking condition 
(c) says that at least one non-empty subset of L \ C, does not get "harmed" by a coalition 
that restricts the outcome to be a subset of L U C (we remove all the players in U \ (L U C) 
from U) and contain every player in C (we add the players in C\L to L). The intuition of the 
third condition will become more clear when we show some important allocation properties 
of GSP mechanisms. 

Theorem 1. A cost sharing scheme gives rise to a group- strategyproof mechanism if and 
only if it satisfies Fence Monotonicity. 
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4.1.1 Examples of Mechanisms that violate just one part of Fence Monotonicity 
and are not GSP 

We will give three representative examples to illustrate, why a cost sharing scheme, which 
does not satisfy Fence Monotonicity, cannot give rise to a group-strategyproof mechanism. 
We chose our examples in a way that only one condition of Fence Monotonicity is violated 
and only at a specific pair L, U. (in fact in condition (c), the violation is present at two pairs, 
however it can be shown that this is unavoidable.) 

Example 1 (a). Let A = {1,2,3,4}. We construct a cost sharing scheme, such that condition 
(a) of Fence Monotonicity is not satisfied at L = {1, 2} and U = {1, 2, 3,4}, as follows. 
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Consider the bid vector b := (6*1, 30, 30). Notice that players 3 and 4 are indifferent 
to being serviced or not, as the single value they may be charged as payment equals their 
bid. Moreover, notice that either player 1 or player 2 (or both) must pay 30 strictly over 
their minimum payment 20 under this restriction. Without loss of generality assume that 
£(i,0(b)) = 30. Consider the bid vector b' := {b\, 6*,, b\, -1). By VP and CS it holds that 
0(b') = {1,2,3} and thus £(1,0(6')) < f(l,0(6)). Notice that the utilities of players 3 and 
4 remain zero, and consequently {1, 3, 4} form a successful coalition. In a similar manner we 
prove the existence of successful coalition when £(2, 0(b)) = 30. 

Example 2 (b). Let A = {1, 2, 3,4}. We construct a cost sharing scheme, such that condition 
(b) of Fence Monotonicity is not satisfied at L = {1,2} and U = {1,2,3,4} for player 3, as 
follows. 
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Consider the bid vector b 3 := (b\, 35, b\). Strategyproofness implies that 3 G 0(b 3 ), 
since otherwise if she is not serviced (zero utility), she can misreport 63 changing the outcome 
to {1, 2, 3, 4} and increasing her utility to 35 — 30 > 0. 

Next, consider the bid vector 6 4 := (b*; b%, 30, 25). Assume that 4 <G 0(b A ). Moreover, 
notice that by VP it is impossible that 3 G 0(b 4 ). Thus, {3, 4} can form a successful coalition 
bidding b' = (6J, &*,, — 1, changing the outcome to {1, 2, 4} increasing the utility of player 
4 to 25 — 20 > 0, while keeping the utility of player 3 at zero. 
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Finally, consider the bid vector 6 3 ' 4 := (b*, b%, 35, 25). Notice that the 6 3, differs with 6 3 
and 6 4 in the coordinates that correspond to players 4 and 3 respectively. Like in the case of 
b 3 the only possible outcomes by VP and CS at 6 3 ' 4 are {1,2,4} and {1,2}. 

Assume that player 4 is serviced at 6 3 ' 4 , which implies that £(4, 0(6 3 ' 4 )) < £(4, 0(6 3 )). 
This contradicts strategyproofness, since when the true values are 6 3 , player 4 can bid ac- 
cording to 6 3 ' 4 in order to decrease her payment and still being serviced. 

Now, assume that player 4 is not serviced at 6 3 ' 4 . Then {3,4} can form a successful 
coalition when true values are 6 3 ' 4 bidding 6 4 , increasing the utility of player 4 to 25 — 20 > 0, 
while keeping the utility of player 3 at zero. 

Example 3 (c). Let A = {1, 2, 3, 4}. This time we construct a cost sharing scheme, such that 
part (c) is not satisfied for L = {1,2} (or {1,2,3}) and U = {1,2,3,4} and specifically for 
C = {3, 4} and j = 3. 
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Suppose that the values are b := (25,25,63,30). The only feasible by VP outcomes are 
{1, 2, 3}, {1, 3}, {2,3}, {3,4} and {3}. Notice that player 4 has zero utility regardless of the 
outcome. 

Assume that 0(b) / {1,2,3} and w.l.o.g that 1 £ 0(b). Then {1,2,4} can form a 
successful coalition bidding b' := (6^, b%, 63, — 1) increasing the utility of player 1 to 25 > 
without decreasing the utility of player 2 (either 0(b) = {2,3} and £(2, 0(b')) = £(2, 0(b)) 
and her utility remains the same utility or 2 ^ 0(b) and her utility increases to 25 > 20, like 
in the case of player 1) and keeping the utility of player 4 at zero. 

Finally, assume that 0(b) = {1, 2, 3}. Then {3, 4} can form a successful coalition bidding 
b" := (25, 25, b* 3 ,b* 4 ). Obviously {3, 4} C 0(b"). Notice that VP excludes each of the following 
outcomes: {1,3,4}, {2,3,4} and {1,2,3,4}. As a result, 0(6") = {3,4} implying that the 
utility of player 3 increases, as £(3,0(6)) > £(3, 0(6")), while player 4 keeps her utility at 
zero. 

If you are given a cross-monotone cost sharing scheme it is rather straightforward how 
to construct a Moulin mechanism. However if you are given a cost sharing scheme that 
satisfies Fence Monotonicity it is not straightforward how to construct a GSP mechanism. 
Fence Monotonicity should be coupled with an allocation rule that satisfies a simple property, 
which we call stability and a valid tie-breaking rule in order for the mechanisms to be GSP. 

4.2 Fencing Mechanisms 

Given a cost sharing scheme £ that satisfies Fence Monotonicity we construct a mechanism, 
that uses £ as payment function and satisfies group-strategyproofness. 

The mechanism takes as input the bids of the players and determines a pair of sets L, U 
where L C U, where L is the set of players that are going to be serviced by the mechanism 
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with strictly positive utility. On the other hand U \ L is the set of players that are indifferent 
between getting serviced or not, because their bid equals their payment, and we use a tie- 
breaking policy to determine which of these players will get serviced. The existence of a 
tie-breaking policy that does not violate group-strategyproofness is guaranteed by part (a) 
of Fence Monotonicity. The intuition behind the tie-breaking rule is that it is optimal for the 
players in L, in the sense that from all subsets of U we choose to serve the one where the 
players in L achieve their minimum payments provided that they all get serviced. 

The mechanisms we design can be put in the following general framework: Given a bid 
vector as input, we search for a certain pair of sets L, U, where L C U C A that meet the 
criteria of stability we define below and then we choose one of the allocations that service the 
players in L according to a valid tie-breaking rule. If the search is exhaustive the resulting 
algorithm is exponential time and we do not know any polynomial-time algorithm. However 
if we restrict our attention to payments that satisfy certain conditions like for example cross- 
monotonicity we can come up with a polynomial-time algorithm for finding a stable pair. 

Definition 5 (Stability). A pair L, U is stable at b if the following conditions are true: 

1. For all i£L,bi> g*(i,L,U), 

2. for alli€U\L,bi = £*(«, L, U) and 

3. for all R C A \ U, there is some i € R, such that 6, < £*(«, L,U UR). 

Remark 1. Assume that £ is Cross-monotonic and let S be the output of Moulin mechanism 
for some bid vector b. Then, the pair L, U, where L = {i € S | 6« > S)} and U = S, is 
the unique stable pair at b. 

After identifying a stable pair these mechanisms output a set S, where L C S QU given 
by a tie-breaking function. 

Definition 6. The mapping a : 2 A x 2 A x M. n — > 2 A is a valid tie-breaking rule for £, if for 
all b and L C U C A, such that L, U is stable at b, for the set S = cr(L, U, b) it holds that 
L C S C U and for all i £ 5, S 1 ) = L, J7). Part (a) of Fence Monotonicity guarantees 
that there exists at least one output S with this property and each different such output gives 
a different tie-breaking rule. 

Definition 7. We will say that a mechanism is a Fencing Mechanism if at input b it finds a 
stable pair L, U at b, outputs a(L, U, b), where a is a valid tie-breaking rule and charges each 
player i, the value £(i,a(L,U,b)). 

It is easy to verify that every Fencing Mechanism satisfies VP, because the players that 
get serviced belong to the set U and as the mechanism satisfies stability these players have 
non-negative utility, and CS, because if a player bids higher than any of his payments, then 
again by stability he belongs to the set L and gets serviced. 

Remark 2. Assume that for two distinct bid vectors b and b', the pair L, U is stable. Then 
for a Valid tie-breaking rule it may hold that a(L,U,b) ^ a(L,U,b'), which implies that 
the outcome of a Fencing mechanism may change, though the utilities of the players remain 
unchanged. If we are not interested in considering the whole class of GSP allocations, that 
arise from cost sharing scheme that satisfies Fence Monotonicity, we can assume that the 
tie-breaking rule depends only on the sets L and U. 
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Remark 3. Moulin mechanisms are GSP and consequently they can be viewed as special case 
of the general framework of Fencing Mechanisms. In Moulin mechanisms £ is cross-monotonic 
and consequently the bigger the set of serviced players, the lower is the cost for each one of 
them. Thus it holds that for all L C U C A, that for all i G U, £{i,U) = £*(i,L,U) and 
the mapping o~(L, U,b) = U for all L C U C A and all b such that L, U is stable, is a valid 
tie-breaking rule. This simplifies the algorithm substantially, as we just have to find a set U 
of players that can be serviced with utility greater or equal to zero. Moreover as the payment 
of each player increases when the serviced players becomes smaller we need the set U with 
maximal cardinality. 

Theorem 2. A mechanism is group- strategyproof if and only if it is a Fencing Mechanism. 

5 Every GSP Mechanism is a Fencing Mechanism 

5.1 Necessity of Fence Monotonicity 

In this section we prove that the payment function of every GSP mechanism satisfies Fence 
Monotonicity. A natural approach would assume that one condition of Fence Monotonicity 
is violated at some L, U, and prove that it is impossible that the corresponding cost sharing 
scheme gives rise to a GSP mechanism. It turns out that our lack of knowledge of the payment 
function renders this approach unlikely to be fruitful. 

Therefore, we will follow an alternative method. We select an arbitrary GSP mechanism 
and consider some U C A. We show that for every L C U the cost sharing scheme satisfies 
each one of the three conditions of Fence Monotonicity using induction on \U \L\. When 
proving the induction step we also reveal several important allocation properties for GSP 
mechanisms. 

Base: For \U \ L\ = 0, i.e L = U every part of Fence Monotonicity is trivially satisfied 
as follows. 

Condition (a): It holds that U, U) = U), since the minimum in the definition of 
£ is taken over the single possible outcome U. 

Condition (b): This condition holds trivially as U \ L = 0. 

Condition (c): Regardless of whether the if condition of this part is true, it holds that for 
all C C U we can set T = U \ C since for all j G T, C U T) = U) = L, U). 

Induction Step: Proving the induction step requires some definitions that allows the 
effective use of the induction hypothesis in order to identify a successful coalition if some 
part is violated. We first define the notion of a harm relation and we prove that it is a strict 
partial order. 

Harm relation 

Lemma 1. If U C U\ and L\ C L, then for all i G U, £*(i,L,U) > L 1} XJx). 

Definition 8 (Harm). We say that i harms j, where i,j G U if and only if £*(j,L,U) < 
Z*(j,LU{i},U) 

Consequently, for all distinct i,j G U, i either harms j or otherwise it holds that 
L,U) = t;*(j,L U {i}, U) (from Lemma [T]). Trivially every i G L does not harm any 
other player j G U. 
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Claim 1. The harm relation satisfies anti-symmetry and transitivity and consequently it is 
strict partial order. 

Corollary 1. The induced sub- graph G[U\L] is a directed acyclic graph. 
Condition (a) of Fence Monotonicity 

The core idea that we will use for the proof of conditions (a) and (b) is to construct bid 
vectors, where VP and CS restrict the possible outcomes to be subsets of U that contain 
every player in L, while for condition (c) we will restrict the possible outcomes to be subsets 
of U. Therefore, we assume that every player in L has bidden a very high value and and 
every player in A \ U has bidden a negative value. 

For the proof of condition (a) , we also want the players in U \ L to be indifferent between 
being serviced and getting excluded from the outcome, i.e. they have zero utility. Thus, we 
assume that every player in U \ L has bidden exactly her minimum payment £* at L, U. 

We first use the induction hypothesis and the properties of the harm relation to prove 
that the following Lemma, which is a condition somewhat milder than condition (a) of Fence 
Monotonicity. 

Lemma 2. For every j € L, there is some set Sj, where L C Sj C U such that for all 
i€S j \L,Z{i,S j )=?{i,L,U) and£(j,S j )=C(J,L,U). 

Then we use the preceding Lemma to show that if the cost-sharing scheme does not satisfy 
condition (a) of Fence Monotonicity then there exists a successful coalition. 

Lemma 3. At the bid vector b, where for alii G L, bi = b*, for alii EU\L, b* = £*(i,L,U) 
and for all i £ U, bi = —1, it holds that L C 0(b) C U and that for all i G 0(b), 0(b)) = 
£*(j,L,U). Setting S = 0(b), condition (a) of Fence Monotonicity is satisfied at L,U. 

Condition (b) of Fence Monotonicity 

We consider now the players in U \ L. Using the induced sub- graph G[U \ L] of the harm 
relation, we can discriminate them by whether a player is sink of this graph or not. First 
we consider the sinks, as the satisfaction of the second condition of Fence Monotonicity for a 
sink is an immediate consequence of the induction hypothesis. 

Claim 2. For every sink k of G[U \ L] condition (b) of Fence Monotonicity is satisfied at 
L,U. 

We continue with the rest players in U\L. 

Claim 3. For every j E U \L one of the following holds: either j is a sink of the sub-graph 
G[U \L], or there is a sink k such that j harms k. 

Now consider an player j in U \ L, that is not a sink of G[U \ L] and let k be one of its 
sinks such that j harms k. In order to prove that the second condition is satisfied for j, we 
will involve group-strategyproofness at certain bid vectors (trying to generalize Example [2] 
where j takes the role of player 3 and k the role of player 4). Prior to defining these inputs, 
we prove another allocation property. 
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Lemma 4. Consider some L' C U' C ^4. Assume that the set Sj, as in the definition of 
condition (b) of Fence Monotonicity exists for some j G U' \ V . At any bid vector b 3 , such 
that for all i G V , b{ = b*, \p. > L f , U') for all i G U' \ (7' U {j}), b{ = f (i, 7', U') and 

for all i i U, b\ = -I, it holds that j G 0(V) and 0{b>)) = CU, L' , U'). 

Let e be a very small positive number, smaller than any positive payment difference. We 
construct two bid vectors, at which we can characterize the allocation of the mechanism. 
First, consider the bid vector b k , where for all i G 7, b k = &*, b\ = £*(k,L,U) + e, for all 
i G U \ (L U {k}), b\ = C(k, L, U) and for all i <£ U, b\ = -1. 

Claim 4. At the bid vector b k the following hold 

(a) Player k is serviced and charged £*(k, L,U). 

(b) Player j is not serviced. 

Second, consider the bid vector b> , where for all i G LU {k}, b\ = b*, b 3 - = L, U) + e, 
for all i G U \ (L U {i,j}), b{ = £*(*, L, 17) and for all % £ U, b{ = -1. 

Claim 5. At the bid vector V the following hold 

(a) For alH G U \ (L U {j, fc}), 6^ = ^*(», L U {A;}, C7) and b 3 = L U {k}, U) + e. 

(b) Player j is serviced and charged 7, ?7). 

(c) Player k is serviced and charged more than £*(k,L, U). 

Finally, we construct the intermediate bid vector where player j bids according to b 3 
(£*(?, L,U) + e) player k bids according to b k (£,*(k, L,U) + e), and every other player bids 
the same value as in both bid vectors. 

Claim 6. At the bid vector W ,k the following hold 

(a) Player k is not serviced at lP ,k . 

(b) Player j is serviced at V ,k . 

(c) 7 C 0(t>>' k ) C U and every player i G 0(^' fc ) \ 7, is charged 7, U). 

As a result setting Sj = 0(b k ), we conclude that the second condition is satisfied for any 
j G U \ L that is not a sink of G[U \ 7] as well. 

Condition (c) of Fence Monotonicity 

To show that the cost-sharing scheme satisfies the third property of Fence Monotonicity, at 
7, U, we need the induction hypothesis only for showing (as we have already done) that 
condition (a) of Fence Monotonicity is satisfied at this pair and specifically the allocation 
properties of Lemma [3l 

The main idea is to define two families of bid vectors, that both contain the previous 
special case and moreover the first family of inputs is a subset of second. 
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U\L 


A\U 


Special Case 


b* 




-1 


First Family 


>?(i,L,U) 


e(i,L,u) 


-1 


Second Family 


>C(i,L,U) 


G M 


-1 
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The use of induction was one of the basic techniques in [5j, however here we need to use 
induction in a more powerful way. In [5] the authors first fix an ordering of the players and 
then apply induction, while here we start from a bid vector that satisfies a certain property 
(induction base) and use induction on the number of coordinates at which the new bid vector 
differs from the bid vector used in the induction base. This allows us to use the induction 
hypothesis more effectively, as we can alter the coordinates of our choice first, instead of 
selecting an ordering and then formulating the induction statement. While the proof of the 
allocation properties about the first family does not require the advantage of this technique, 
it is the essence of our proof of the corresponding allocation properties about the second 
family. 

Notice that the special input differs from the bid vectors of the first family only in the 
bid coordinates that correspond to players in L. We apply our technique and extend the 
implications of Lemma [3] for every bid vector in the first family. 

Lemma 5. For every bid vector b, where for all i G L, b\ > £(i,S), for all i G U \L, 
h = L, U) and for all i £ U, b{ = —1, it holds that L C 0(b) C U and for all i G 0(b), 
((i,0(b))=e(i,L,U). 

Next we provide a weaker allocation property about the inputs of the second family. We 
arbitrarily select a vector that belongs to the first family and then apply our technique for 
proving this property for every input that is "reachable" by our initial vector by altering the 
coordinates that correspond to the players in U \ L. The arbitrary selection of the initial 
vector ensures that our statement holds for every input that belongs to the second family. 

Lemma 6. For every bid vector b, where for all i G L, b{ > S), for all i G U \ L, b{ G R 
and for all i g U, h = -I, it holds that: for all i G 0(b), f (£, 0(b)) > L, U). 

This Lemma may shed some light on the understanding of the GSP mechanisms and can 
be interpreted as follows: Assume that the players in A \ U are uninterested to participate. 
Now if all the bids of players in a set LOU have surpassed their respective minimum 
payments at L, U, then a GSP mechanism never excludes a group of players in L from the 
outcome in order to charge a serviced player less than the restriction of their presence. Loosely 
speaking the players in L "fence" any outcome C C U such that there is some j G C such 
that £(j,C) < £* (J, L,U). Since this "fencing" phenomenon must be true for arbitrary bids 
of the players in U \L, it follows that every GSP cost-sharing scheme must satisfy condition 
(c) of Fence Monotonicity, as shown below. 

Claim 7. We construct the bid vector b as follows: For all i G C, bf = b*, for alH G L \ C, 
b<? = £*(i, L,U) + e and for alH g C U L, bf = -1. 
For the bid vector b c it holds that: 

(a) For all i G 0(b c ) it holds that f (*, 0(b c )) > £*(*, L, U). 

(b) C C 0(b c ) QLUC. 

(c) For all i G 0(b c ) \ C, it holds that f (i, 0(b c )) = £*(», L, U). 
Setting T = 0(b ) \ C we complete the proof of the third condition. 
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5.2 Necessity of Stability and Valid tie-breaking 



In the last part, we show that the allocation of every GSP mechanism satisfies Stability and 
uses a Valid tie-breaking rule. We already know that the payment function satisfies Fence 
Monotonicity and thus we can prove the following generalization of Lemma [5j 

Lemma 7. Let L C U C A. For every bid vector b, such that for all i £ L, bi > L, U), 
for all i £ U \L, bi = £*(i,L,U) and for all R C A \ U, there is some i G R such that 
^ < £*(i,L,UUR), it holds that L C 0(b) C U and for alii € 0(b), £(i,0(6)) = £*(i,L,U). 

Lemma [T3l implies that there is a stable pair at every input. Thus, given a bid vector, 
we may apply Lemma [7] with L, U being the corresponding stable pair at this input, and get 
that L C 0(b) C U (Stability) and for all i e 0(b), £(i,0(b)) = £*(i,L,U) (Validity of the 
tie-breaking rule). 

6 The classes of GSP and Fencing Mechanisms coincide 

In this section, we complete our characterization by proving that Fencing Mechanisms are 
GSP. 

6.1 Properties of Stable pairs 

Lemma 8. For every bid vector b and set L with L C A, there exists a unique maximal set 
U , U 2 L, such that for all i € U \ L we have bi > £*(i,L,U) and any other set with the 
same property is a subset of U. Moreover, the pair L, U satisfies condition 3. of Stability 

Consider all possible outcomes of the mechanism, that contain every player in L. Now 
we remove all the sets S, where at least one player i 6 S\L, has bidden strictly less than her 
payment in S. The set U is the union of all the sets that remain after this filtering. Notice, 
that this is always true only if the underlying cost sharing scheme satisfies condition (b) of 
Fence Monotonicity. 

Furthermore, notice that we haven't yet shown that that there is a stable pair at every 
input. The next two properties will be used together in our proofs as a criterion whether a 
pair L, U is stable at a given bid vector b. 

Lemma 9. Suppose that L,U is a stable pair at the bid vector b and that S is set with the 
property that for all i £ S we have that bi — S) > 0. (If the mechanism would output S 
then all players are would have been served with non-negative utility.) If 

(a) S <£U, or 

(b) if S C U and for some i G S we have L, U) > 5), 

there exists some non-empty set T C L\ S , such that for all j € T we have £(j, S L)T) < bj. 

This lemma is an immediate consequence of part (c) of Fence Monotonicity and the 
definition of stability. 

Lemma 10. Suppose that L C S C U and that there exists a non-empty T C A\S such that 
for all i E T we have bi > S U T) and that for at least one player from T the inequality 
is strict. Then L, U is not a stable set at the bid vector b. 
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6.2 Uniqueness and group-strategyproofness 

Lemma 11. If for some bid vector b there exists a stable pair then it is unique. 

A crucial point of our proof is that for the following step we assume that if there exists a 
stable pair the mechanism produces an outcome, otherwise it terminates without providing 
an answer. We will first show that the mechanism is GSP, wherever there exists a stable pair. 
Then we will use the fact that the mechanism satisfies group-strategyproofness for inputs 
that have a stable pair, to prove the existence of a stable pair for every input. 

Lemma 12. For the inputs where there exists a stable pair, every Fencing Mechanism is 
group- strategyproof. 

Proof. Let b and b' be two bid vectors, and let L, U and V , U' be their corresponding unique 
(from Lemma [TT]) stable pairs and 0(b) and 0(b') the corresponding outputs. Assume towards 
a contradiction that some of the players can form a successful coalition when the true values 
are b reporting b' . 

We will first show that any player i served in the new outcome, i € 0(b'), has non- 
negative utility i.e. bi > £(i,0(b')). Take some i that is output in 0(b'). If bi = b[ then 
it holds trivially since the mechanism satisfies VP at the outcome 0(b'). If bi ^ b\ then % 
changes his bid to be part of the coalition and consequently his utility after this coalition is 
non-negative, which gives bi — £(i,0(b')) > 0. 

The next step is to apply Lemma[9]to show that there exists some non-empty T C L\0(b') 
such that for all i £ T we have bi > £(i,0(b') U T). If 0(b') % U then the premises of the 
Lemma hold trivially. 

Suppose that 0(b) C U. For the coalition to be successful the utility of at least one player 
j increases strictly when the players bid b' consequently j € 0(b') and bj — £(j,0(b')) > 0. 
We will show that £*(j,L,U) > £(j,0(b')). If j is not served at b and since 0(b') C U from 
stability we get that j G U \L and bj = L, U) > 0(b')). If j is served at b then her 
payment equals £*(j,L,U) by the definition of the mechanism and in order that she profits 
strictly it must be £(j,0(b')) < L,U), so we can again apply Lemma[H 

Finally we will show that for alH E T we have bi = b' i . After the manipulation the players 
in T are not serviced, while as T C L from stability we have that in the truthful scenario the 
players in T are serviced with positive utility. Consequently the players in T wouldn't have 
an incentive to be part of the coalition and change their bids. 

Putting everything together we get that there exists a T C A \ 0(b') such that for all 
i € T we have U i > £(i,0(b') U T), which by Lemma [TU1 contradicts our initial assumption 
that L', U' is stable at b' . □ 

6.3 Existence of a stable pair for every input 
Lemma 13. For every bid vector b there exists a unique stable pair. 

Proof. Let b* be some value that is big enough so that player i always gets serviced, you 
can let 6* > maxgc„4 S), since the allocation of the mechanism satisfies Stability. We 
will show that there exists a stable pair at any input b by induction on the number m of 
coordinates that are less than b*, i.e. on the number m = \{i \ bi < b*}\. 
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Base: For m = 0, we only have to show that there exists a stable pair for the bid vector 
(6*, . . . , 6* ) and A, A is a stable pair. 

Induction Step: Suppose that if a bid vector has m — 1 coordinates that are less than 
b*, then it has a stable pair. We will show that if a bid vector b has m coordinates that are 
less than b* then it also has a stable pair. We will suppose towards a contradiction that there 
exists no stable pair at b. 

We first need some definitions. Let L* := {i \ b{ > b*} and U* the corresponding (from 
Lemma E]) maximal set. Notice that for all i G L*, b% = b* > £*(i,L* ,U*) by the definition of 
b*, which implies that the pair L* , U* satisfies the first condition of stability. Moreover, from 
Lemma 6 we get that the third condition of stability is satisfied for L*, U* as well. Thus, as 
L* , U* cannot be stable at b (from our assumption), the set W = {i \ i G U* \ L* and b{ > 
£*(i,L*, U*)} should be non-empty. 

For each i G W we define a corresponding pair Li, C/i as follows: The pair Li,Ui is the 
unique (by Lemma [TTj) stable pair of (b*,b-i), which exists by the induction hypothesis. 

Claim 8. If Lj, f/j is the stable pair of (b*, b-i), then 
(a) L* U {i} C Li and (b) U { CU*. 

(c) If j G Li \ (L* U {£}) then j G W and bj > C(L*, U*) . 

Claim 9. If there exists no stable pair at b, then for all i G W we have 

(a) h <Z*(i,Li,Ui). 

(b) L* U {i} C L { . 

Since W ^ there exists some i £ W such that Lj has minimum cardinality, i.e. i = 
argminjgvi/ |Lj|. By Claim [9] (b) there exists some j G Lj \ (L* U {i}) and by Claim [8] (c) 
j G W. We will show that Lj C Lj contradicting the choice of i. 

Claim 10. If there exists no stable pair at b and j G Lj \ (L* U {i}) then 

(a) The pair Lj, Lj is stable at the bid vector (6*, b*,b_^ jy). 

(b) -•(./. /. ; , Uj) > Li, Ui) and % $ Lj. 

(c) If there exists some k G Lj \ Li, then the mechanism is not group-strategyproof at 
inputs where a stable pair exists. 

Now since j £W and from Claim [TOli ^ Lj and for every k G Lj we have that also k G Lj, 
we get that Lj C Lj, which completes the proof. □ 

7 A lower bound for the Budget Balance of any GSP mecha- 
nism 

In the last section we demonstrate the use of our characterization by showing that even in 
the case of three players there is a family of cost functions parameterized with a variable x, 
where every GSP mechanism cannot achieve better budget-balance than -. 

First, we show some consequences of Fence Monotonicity for small numbers of players, 
that will simplify the use of it. 

Proposition 1. Let £ be a cost sharing scheme, that satisfies Fence Monotonicity. For all 
S C A and two distinct i,j G S, if ' S \ {i}) < S) then 
(a) For all k G S\{i,j}, £(k,S\{i}) <£(k,S) 



16 



(b) Z(i,S\{j})<Z(i,S). 

(c) ai,s\{j})>t(i,s). 

(part (a) is an alternative definition of semi- cross monotonicity (fEj)) 

Every part of the preceding Property, is implied by the corresponding condition of Fence 
Monotonicity. Moreover, part (b) and (c) fully characterize the case of two players. However, 
this Property is far from characterizing the case of the three players, as there are many other 
constrains, that are not captured by its implications. 

Theorem 3. Let A = {1,2,3}. Consider the cost sharing function defined on A as follows: 
C({1,2}) = C({1,3}) = 1, C({1}) = C({2}) = C({3}) = x, C({2,3}) = x 2 + x and 
C({1, 2, 3}) = x 3 + x 1 + x, where x > 1. There is no ^-budget balanced cost sharing scheme, 
that satisfies Fence Monotonicity. 

It is important to understand that for the proof of this theorem, we use every implication 
of Proposition 1 and thus every condition of Fence Monotonicity. 

8 Complexity and open questions 

Does there exist a polynomial-time algorithm for finding the allocation of a cost-sharing 
scheme that satisfies Fence Monotonicity or maybe we can show that the problem of finding 
a stable pair is computationally hard? 

A natural question that arises in this context is whether, it is computationally more effi- 
cient to find the appropriate outcome than identifying the stable pair. Suppose that you have 
an algorithm that computes the outcome of a GSP mechanism. It is rather straightforward 
how to compute the lower set L of the stable pair, simply by checking which players have 
positive utility. What remains is to find the upper set U, which is exactly the maximal set, 
as defined in Lemma [HJ 

Theorem 4. Suppose that we are given the outcome of a group- strategyproof mechanism at 
b. Given that we have already computed L, U) for all L C U C A and all i € U , there is 
a polynomial time algorithm for identifying its stable pair. 

We believe that some other interesting directions for future research are the following: 
How can our characterization be applied for obtaining cost-sharing mechanism with better 
approximation and budget-balance guarantees or lower bounds for specific problems? And 
finally can our techniques be extended to obtain a characterization of weak-group-strategy- 
proof cost-sharing schemes? 
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A Missing proofs of Section 5 

Proof of Lemma Q] 

It is obvious that the minimum payment of player i can only decrease as the set of outcomes, 
over which the minimum in the definition of is taken, becomes larger. □ 

Proof of Claim Q] 

We show this using the induction hypothesis at every LU{i},U for every i G U\L and more 
specifically condition (c) of Fence Monotonicity. 

To show anti-symmetry we need to consider only elements of U \ L, as trivially it is 
impossible that some i G L harms any other elements. Consider two distinct i,j G U \ L 
and assume that i harms j, that is ^*(j,L,U) < L U {i},U). From definition of ^* 
there is a set Sj, where j G Sj, L C Sj C U and £(j,Sj) = £* (j, L,U). Notice that by 
our assumption it is impossible that i G Sj, since L U {i},U) > £{j,Sj). It follows 
that Sj C U and by using condition (c) of Fence Monotonicity at L U {i}, U, we get that 

Sj U {i}) = L U {i}, U) = C{i, L, U) (the only non-empty subset of (L U {i}) \ Sj is 
{%}). Since LU {j} C Sj U{i}Cf/ we get that £*(*, L U {j}, U) = £*{i,L,U). 

We show transitivity of the harm relation in a similar manner. Consider three distinct 
players i, j and k, where i,j G U \ L and k G U (may also belong to L). Assume now 
that i harms j, j harms k while i does not harm k. We will show that this contradicts our 
induction hypothesis. Since ^*{k,L,U) = ^*{k,L U {i},U), it follows that there is some set 
Sk, where L U {i} C S^ C U such that Sk) = L, U). Using similar arguments like in 
the previous part we show that xi(j, Sk U {j}) = £*(j, L, U) and as L U {i} C Sk U {j} C U 
we reach a contradiction from our assumption that £*(j, L, U) < L U {i}, U). □ 

Proof of Lemma [2] 

(a) We first have to prove the following Claim, which is an immediate consequence of the 
fact that the harm relation is a strict partial order. 

Claim 11. For every j G L one of the following holds: either every i G U \ L harms j, or 
there a k G U \ L that does not harm j and also is a sink of G[U \ L]. 
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of Claim [771 Suppose that there is some i G U \ L that does not harm j. If i is a sink of 
G[U \ L], setting k = i completes our proof. Otherwise, there must be a path that goes 
through i but does not stop there. Let k be the sink of this path (G[U \ L] is a directed 
acyclic graph). 

Notice that transitivity implies that i harms k. Thus, it is impossible that k harms j, 
since using transitivity again we would deduce that i harms j contradicting our assumption. 

□ 

Consider some j G L. We split the proof in two cases as Claim [TT1 indicates. 

Case 1: Suppose that every i G U\L harms j. This implies that £*(j,L,U) = £,(j,L) 
and hence we can set Sj = L, since the requirements of Lemma [3] are trivially satisfied, since 
Sj\L = 0. 

Case 2: Consider some sink k that does not harm i. Using induction hypothesis at 
L U {k}, U and in particular part (a) we get that there is a set S, where L U {k} C S C U 
such that for all i G S, £,(i,S) = t;*(i,L U {k},U). Using the fact that A; is a sink and 
also does not harm j we get that for all i G S' \ L, £,*(i,L U {k}, U) = £*(i,L,U) and 
L U {k}, U) = L, U). As a result, we can set Sj = S. □ 

Proof of Lemma [3] 

By CS and VP the output of the mechanism satisfies L C 0(b) C U . First note that in any 
case a player i G U \L has utility zero: either she is not serviced, or by VP, if she is serviced 
her payment cannot exceed her bid and cannot be less than her minimum payment L, U) 
so 0(b)) = hi = C(h L, U). What remains is to show that j is also served at L, U). 

Moreover, suppose towards a contradiction that for some player j G L, £(j,0(b)) > 
L, U) (If the set U \ L is empty U = L it is impossible that some j G L is charged more 
than L, U) = L)). Then she could form a coalition with the players in U \L, who 
would enforce the set Sj , where Sj is the set guaranteed to exist by Lemma [21 to be output 
i.e. the players i G U \ L could change their bids to b* if i G Sj and — 1 if i G" Sj, so that by 
CS and VP the output is Sj. 

Since for every i G Sj \ L, £,(i,Sj) = £,*(i,L,U) their utilities remain zero after this 
manipulation (the same holds trivially for alii G U \ Sj) , while the utility of player j strictly 
increases, and thus the coalition is successful indeed. 

Consequently for all j G L, j G 0(b) and £(j,0(b)) = £*(j,L,U) and the players in 
0(b) \ L are charged at their minimum payment as well. □ 

Proof of Claim [2] 

Using the induction hypothesis at LL){k}, U we get from part (a) that there is a set S, where 
LU{k} C S CU, such that for all i G 5, S) = L U {k}, U). Using now the fact that 
k is a sink we have that for alH G S\L, L, U) = L U {k}, U). Thus, setting Sk = S 
we satisfy condition (b) of Fence Monotonicity for k at L, U. □ 

Proof of Claim [3] 

If j is not a sink if G[U \ L], there must be an path starting from j, which obviously ends at 
a sink k of this graph. Transitivity implies that j harms k. □ 
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Proof of Lemma [4] 

Like in the proof of the Lemma [3l by CS and VP we get that L' C 0(W) C U' and thus from 
the definition of the bid vector and £*, every player in U' \ (L' U {j}) has zero utility. We 
need to show that j is serviced and charged £*(j,L', U'). 

Moreover, suppose towards a contradiction that player j, is either not serviced or she is 
charged an amount greater than L', U'). Since we assumed that condition (b) of Fence 
Monotonicity is satisfied for j at L',U' , there must be a set Sj with V C Sj C U', j G Sj and 
for all % G Sj \ L' , £(i,5j) = L' ,U'). Obviously if she is serviced at a higher payment 
then she prefers the set Sj to the current outcome. Also, the same holds if she is not serviced, 
as we assumed that bj > (J, V ,U') = £,(j,S) and thus her utility would be to a strictly 
positive if the outcome was Sj . In similar manner like int the proof of Lemma [3] she could 
form a coalition with the players in U' \ {V U {j}) by enforcing S to be output. Again our 
assumption about the payments of the rest players in Sj \ L 1 implies that their utility remains 
unchanged thus this coalition is successful. □ 

Proof of Claim |4] 

(a) We get that player k is serviced and charged £*(k,L, U) by applying Lemma 0] for k with 
L' = L and U' = U. 

(b) Suppose towards a contradiction that j G 0(b k ). The payment of player k would be 
lower bounded by £*(k,L U {j},U), since L U {j} C 0{b k ) C U, which contradicts with the 
fact that k is charged £* (k, L,U), which is strictly lower by our assumption that j harms 
k. □ 

Proof of Claim [5] 

(a) Since k is a sink of G[U \L], we have that for all % G U \ (L U {j, k}), L U {A;}, U) = 
C(i, L, U) = b{. Similarly, we get that L U {k}, U) + e = L,U) + e = bj. 

(b) We apply LemmaU]for j with L' = LL){k} and V = U, since condition (b) is satisfied 
for j at this pair (induction hypothesis) and the bid vector satisfies the requirements of this 
Lemma, (b- = b* for all i G L U {k}, b 3 i = —1 for all % ^ U and using Claim [5] (a).) As a 
result, j G O(feJ') and £(j,0(b?)) = i U {A;}, C/) = C(j,L,U). 

(c) From part (b) we get that the set 0(b k ) satisfies that L U {j} C O(b) C [7, and thus 
the payment of player k is lower bounded by L U {j}, [/). Since j harms k we get that 

LU {j}, Z7) > £*(k,L,U) completing our proof. □ 

Proof of Claim © 

(a) Assume that player k is serviced at V' k . Notice that by VP and the definition of e, if k 
is serviced at V' k then her payment cannot exceed £*(k,L, U). Additionally, notice that the 
only coordinate ti )k differs from V is the bid of player k. Thus, strategyproofness is violated 
from V , since from Claim [5] the payment of k decreases. 

(b) Suppose that j is not serviced at V ,k . Then {j,k} can form a successful when true 
values are b k bidding b^' k , since from Claim H] the utility of k increases from zero to e and the 
utility of j is kept to zero (she is not serviced at either input). 
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(c) By VP and CS we get that L C 0(b) C U, thus the payment of every serviced player 
i is lower bounded by £*(i,L,U). By definition of b 1 ^ and VP of the mechanism we get the 
equality for every player in 0(b) \(XU {j})- Moreover, from the definition of e, we conclude 
the same for j. □ 



Proof of Lemma 

We will prove our statement with induction on the cardinality of the set T = {i £ L \ bi ^ b*}. 
Base: Since T = 0, we simply apply Lemma [3l 

Induction step: For the induction step we will show that L C 0(b) C U and for all 

i £ L, £(i, 0(b)) = L, U). Then it is easy to see that every i £ 0(b) \ L must be serviced 
at L, U) by VP and the definition of £*. 

By the construction of the bid vector we have that 0(b) C U. Consider now some j £ T. 
Induction hypothesis implies that j is serviced and charged £*(j,L,U) at the bid vector 
(b*, Suppose that j is not serviced at b resulting in zero utility. Since bj — ^*(j, L, U) > 
she can misreport b* so as to increase her utility to a strictly positive quantity and thus violate 
the strategyproofness of the mechanism. As a result, j must be serviced at b and hence by 
strategyproofness j must be serviced at the same payment, (since j is an arbitrary element 
of T, the same holds for all j £ T). 

Now since j is indifferent between the two outcomes group-strategyproofness requires the 
same about the rest players. This is only possible i € L \ T (i € 0(b) by CS since bi = b*) 
is charged the same payment in either input i.e. ^(i,0(b)) = ^(i,0(b*^b-j)) = £*(i,L,U) 
(induction hypothesis). □ 



Proof of Lemma [6] 

Let b° be any bid vector satisfying the conditions of Lemma which means that for alii E L, 
6° > £*(t, L, U), for alH £ U \ L, 6? = L, U) and for all i <£ U, 6° = -1. Then we relax 
the constrains we put on the bids of the players in U \ L (the rest players bid always according 
to b°) and prove that no player becomes serviced at a price strictly less than her minimum 
payment at L,U, by using induction on \T\, where T := {i £ U \ L \ bi ^ h®}. 

Base: For T = we have that 6 = 6° and the allocation property follows from Lemma EJ 
Induction step: Assume that there is some j £ 0(b) that is charged less than £*(j, L, U). 
Since by VP 0(b) C U, either j £ L which implies that 6° > £*(j, L, U) or j £ U \ L and 
thus 6° = L, U). In both cases we have that 

j £ 0(b) and £(j, 0(b)) < L, U) < b% (1) 

We will prove that there exists at least one successful coalition, contradicting the assumed 
group-strategyproofness of the mechanism. The key of our proof is the definition of the 
following special subset of T 

R := {i £ T | i £ 0(b) and f (t, 0(b)) > 6°} (2) 

(notice that j £ R). 

This set is a special subset of T that can be interpreted as follows: If the true valuations 
are given by b° and the players in T bid according to b, then the set R represents the players 
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that their utility becomes negative, and since every i G R had zero utility at b° (Lemma [5]) , 
this gives us the set of liars that sacrifised their utilities. Notice that the set R not being 
empty renders the manipulation we considered unsuccessful. For proving the induction step 
we consider two cases regarding R. 

Case 1: If R C T, we construct the bid vector where for every i G R, b\ = bi and for 
every i R, b[ = b® . We complete the proof of this case by showing that (T \ R) U {j} form 
a coalition when true values are b' bidding b. 

First, we prove that in the truthful scenario every player i G T \ R has zero utility and 
non- negative after the misreporting (profile b). By using induction hypothesis at b' (differs 
with 6° in \R\ < \T\ coordinates) we get that for every i G T \ R such that i G 0(b') (the 
rest players have obviously zero utility), it holds that £*(i,L,U) < £(i,0(b')) < b' i? where 
the last inequality follows from VP. Since i G T \ R, we get that b\ = b\ = £*(z, L, U) and 
thus b[ = (,(i,0(b')). Now consider the outcome after the misreporting. Either i £ 0(b) 
and hence she has zero utility after the misreporting or i G 0(b) and her utility becomes 
6- — £(i,0(6)) = 6? — £(i,0(b)) > 0, where the last inequality follows from Equation [2] as 
ieT\R. 

Second, we prove that player j strictly increases her utility. Considering the truthful 
scenario there are two cases for j: She is serviced at b' and charged £(j, 0(b')) > ^*(j,L,U) 
from the induction hypothesis. From Equation Q] we get that j is serviced after the misre- 
porting and charged £(i,0(b)) < £*(j,L,U), and thus her payment decreases, while she is 
still serviced. Now if j is not serviced at b', then she has zero utility. From Equation [T] we get 
that b® > £(j, 0(b)) and since j R it follows that b® = b 1 -. As a result, her utility increases 
to b'j-ZU, 0(b)) >0. 

Case 2: Otherwise if R = T, we construct the bid vector b" , where every i G fi, 
b'( = £(i,0(b)) and every i £ R, b'( = 6j. Notice that for all i G R, b { > b'( by VP at b 
since R C 0(b). Moreover, for every i ^ R, b" = b®, since R = T. 

Claim 12. If T = R and there is some j that satisfies Equation [H then for the bid vector 
b", it holds that R U {j} C 0(b") and for alH G R U {j}, 0(b")) = 0(b)). 

of Claim{]M For all S C i?, we define the bid vector b , where for all i G S, bf = b'[ and 
for all i S, bf = hi. Notice that since we assumed that T = R, it holds that bf = 6° 
for all i R and all SCR. We show that for all S C i?, i? U {j} C 0(6 S ) and for all 
« G -RU {j}, £(i, 0(b s )) = £(i, 0(b)), with induction on \S\. We will refer to this induction as 
second induction to discriminate it from the first. After proving this statement, we can set 
S = R (b R = b") and complete the proof. 

Base (second): If S = 0, i.e. 6® = b, then every condition holds trivially. 

Induction step (second): If for some i G S, it holds that b'( = bi, then the induction 
step follows trivially from induction hypothesis as b s = (bi,bf_i) = b s ^ l \ 

Now assume that for all i G S, b" < bi and consider some i € S. Player i is serviced 
at (bi,b_i) and charged £(i,0(b)) (induction hypothesis). Strategyproofness implies that by 
lowering her bid up to her payment, which gives us the bid vector b s , if she is serviced, then 
her payment must be the same, i.e., 

for all i G S n 0(b s ), f (i, 0(b s )) = £(*, 0(b)). (3) 

This Equation implies that if the true values are given by b s , then every player in S has 
zero utility. Moreover, by misreporting b they are charged an amount equal to their true 
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value and thus their utilities is kept at zero. Group-strategyproofness implies that no player 
in A\S has incentives for this misreporting. Notice that bj = b® since j ^ R = T. Moreover, 
from Equation [1] we have that 6° > £*(j,L,U) > £(j, 0(6)) and thus her utility after the 
manipulation we described is given by bj — £(j, 0(b)) > 0. In order that this amount is not 
bigger than her utility in the truthful scenario (6 s ), it holds that 

j £ 0(b s ) and £(j,0(6 s ) < £(j,0(6)), (4) 

which together with Equation [1] and the fact that bj = b® implies that 

Z(j,0(b s ))<e(j,L,U)<bf. (5) 

Using the latter equation we show that R C 0(b s ). Assume that some % £ R is not 
serviced at b . First, we show that i is not serviced at (6?,6 S j). There are two cases for 
i: Either bf = b" if i £ S or bf = bi > 6" if i £ R \ S. In any case bf > b" > 6?, where 
the second inequality follows from the definition of R (Equation [2]) since 6" = £(i,0(6)). 
Strategyproofness implies that if the true values are b s and i reports 6^ (the bid vector 
becomes (6^,6^)), then she is not serviced as otherwise her payment cannot exceed 6^ by 
VP and thus her utility increases to bf — 6? > 0. 

Now we show that if i is not serviced at (6^,6^), then from a successful coalition 

when true values are (6?,6 S J bidding 6 s . The utility of player i is kept to zero, as she is 
excluded in both inputs from the outcome. Notice that by the first induction hypothesis at 
the bid vector (6?,6_j) (differs with 6° in \R\ — 1 = \T\ — 1 coordinates) there are two cases 
for j: Either j is serviced and charged 0((6°, bf_ { ))) > £*(j,L,U) and thus her payment 
decreases to £(j, 0(b s )) < L, U) (from Equation [5]) or she is not serviced and her utility 
becomes bj — (,{j,0(b s )) > (from Equation [5]) . 

As a result, it holds that S C R C 0(b s ) and together withU]we get that for every i £ S, 
£(i, 0(b s )) = £(i, 0(6)). Therefore, the players in S are indifferent between the two inputs, i.e 
regardless of which of the two we consider as true values, they can misreport the other without 
losing utility. Group-strategyproofness implies that the other players are indifferent as well, 
which is only possible if for all? £ R \ S, £,(i,0(b s )) = £(i,0(b)). Moreover, from Equation 
H]we get that j £ 0(b s ) and for similar reasons it holds that i(j,0(b s )) = £(j,0(b)). □ 

By VP we have that 0{b") C U (for every i £ A \ U, it holds that i £ R and thus b" = 
6- 1 = —1). Furthermore, from Claim[12]and Equation [1] we get that £(j,0(b")) < L,U). 
Therefore, the definition of £* implies that L % 0(6"). 

Assume that the true values are given by b". Every player k £ (L \ 0(b")) has obviously 
zero utility. From Claim [12] we deduce the same for every i £ R. We complete our proof by 
showing that R U (L \ 0(b")) form a successful coalition bidding 6°. 

First, we prove that the utility of every % £ R remains non- negative after the misreporting. 
Consider some i £ R such that i £ O(b ) (obviously the rest players have zero utility). From 
Lemma [5] it holds that £(i,0(6°)) = £*(i,L,U) and since 17) =6° (t € U \ L) and 

W L < £(£, 0(6)) = b'( (Equation[2D, we conclude that her utility increases to O(6 )) > 0. 

Second, we show that the utility of every k £ L \ 0(6") increases, as it becomes strictly 
positive. Since k £ R we get that 6' fc ' = b° k . Moreover, since k € L we have 6^ > £*(k,L,U) 
and from Lemma [5] we get that k £ 0(6°) and £(fc,O(6 )) = £*(k, L,U). As a result, her 
utility becomes - £(fc, 0(6°)) > 0. □ 
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Proof of Claim [7J 



(a) We can apply Lemma [6] as every condition is satisfied. 

(b) VP and CS implies C C 0{b c ) C L U C. C C <3(6 C ) follows from (a) and our 
assumption that C) < L,U). 

(c) From definition of e we have that for all i G 0(b c ) \ C, £(i,0(b c )) < £*(i,L,U). 
Together with (a) we get the equality. □ 

Proof of Lemma [7J 

Notice that Lemma implies the same allocation property in the special case, where every 
i G A \ U has bidden —1. In order to show this Lemma we will use the same induction, 
i.e. we show that L C 0(b) and for all i G 0(b), £(i,0(b)) = £*(i,L,U) using induction on 
m=\{ieL\bi^b*}\. 

Base: First, by CS we have that L C U. Next, we show that not player in A \ U is 
serviced. Suppose that the set R = 0(b) \ U ^ 0. We will show that VP is violated. By 
the definition of the bid vectors we consider it holds that there is some i G R, such that 
bi < L,UUR) < 0(b)) (since L C 0(b) CUUR) and thus we reach a contradiction. 

As a result, it holds that L C 0(b) C U. Thus, for every i G 0(b), we have that 
£(i, 0(b)) > £*(i, L, U)). By VP we get the equality for every i G 0(b) \ L. Now assume that 
the previous inequality is strict for some j G L. We show that the players in (A \ U) U {j} 
can form a successful coalition, where every i ^ U announces —1. 

Trivially the utilities of these players are kept to zero after the misreporting and applying 
Lemma [5] we get that j is serviced and charged L, U) < 0(b)). 

Induction Step: We show that L C 0(b) and for all i G L, £(i,0(b)) = £*(i,L,U) 
exactly like in the proof of Lemma [5l Now since L C 0(b) in similar way we show that 
U C 0(b). Thus, this restriction together with the definition of the bid vector, implies that 
for every i G 0(b) \L, £(i,0(b)) = £*(i,L,U). □ 



B Missing Proofs of Section 6 

Proof of Lemma [8] 

Assume towards a contradiction that there exist two distinct sets U\ , U2 none of which is a 
subset of the other that both satisfy this property. Then we could construct the set Ui U U2 
which also satisfies the same property and is a proper superset of both Ui and U2 reaching 
a contradiction. Indeed for all i G U% \ L we have bi > £*(i, L,Ui) > ^*(i,L,U\ U U2) as 
the minimum payment of player i can only decrease as the set of outcomes, over which the 
minimum in the definition of ^* is taken, becomes larger. A similar inequality holds for the 
players in i G U2 \ L completing the proof. 

Now we show that if U is the maximal set with this property, then L, U satisfy property 
3. of stablity. Consider some non-empty R C A\U. Assume that for all i G R, bi > 
£*(i, L, U U R). From Lemma [H we have that for all i G U \ L, bi > L, U U R) and thus 
we reach contradiction by the maximality of U. □ 
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Proof of Lemma [9] 

We will first show that if S % U then there exists some i G S we have 7, £7 US') > £(i,S). 
Since 7, £7 is stable (property 3.) there exists some i G S \ £7 such that 6j < £*(i,L, U U S) 
and since from the initial assumption 5) < b{ we get that 5) < 7, £7 U S) 

The rest of the proof is the same for both cases (note that in what follows, if S C 17 then 
S U U = £7). Note that S C £7 U S, since L ^ S. Applying part (c) of Fence Monotonicity 
we get that there exists a non-empty TCI\S such that for all j G T we have £(j, SUT) = 
£*(j, 7,£7 US) < L,U), where the last inequality is by the definition of £*, since the 
minimum cannot decrease as the set of outcomes over which it is taken becomes larger. From 
property 1. of stability and since TCI, for all j G T we have 7, £7) < 6j. Consequently 
for all j € T we have f (j, S 1 U T) < □ 

Proof of Lemma 1101 

Suppose towards a contradiction that L, £7 is stable at b and that there exists some T C ^4\5, 
such that for all ? € T, bj > 5UT) and that for at least one player the inequality is strict. 

Since 7 C S'UTC £7 U T from the definition of £* we get that for all % £ T we have 
C(i, L,UUT)< L, U) < f (i, 5 U T). 

If T C £7, then there exists some i E T such that b{ > £(i,S UT) > £*(i,L,U). Since 
T A \ L this contradicts with stability (condition 2.) of 6 at L, £7. 

If T % £7, then T \ £7 is not empty and for all i G T \ £7 we have b% > £(i, SUT) > 
L, £7 U T), which contradicts with stability (condition 3.) of b at 7, £7. □ 

Proof of Lemma 1111 

Assume first that L\ ^ L2 and without loss of generality that L2 % L\. Consequently there 
exists some j G L2 \ L\. 

By Fence Monotonicity (part (a)) there exists a set S2 such that L2 Q S2 C £72 and 
^(i, 1S2) = C*(*,72,£72) for all i G S^. Notice that for all j G 52, bj > £(j, S2), where strict 
inequality holds only if j G 72 . The idea is to apply Lemma [9] and get that there exists a 
non-empty T C 7 \ S2, such that for all i G T we have \ > S2 U T). We will then apply 
Lemma [10] to show that 72, £72 is not stable at b which contradicts our intial assumption. 

It only remains to show that we can apply Lemma [9l If S2 % U2 this is immediate. 
Suppose that S2 C £7i. If j G L2 \ L\ then also j G £7i \ L\ thus from stability (condition 
2.) of 7i,£7i, we get that 6j = 7i,£7i) and from stability (condition 1.) of 72, £72 and 
since j E L2, we get that 6j > £(j, S?)- Therefore, we get that S2) < £*(j,Li,Ux) and 
consequently S2 satisfies the requirements of Lemma [9l 

We showed that L\ = L2 = 7. Suppose towards a contradiction that £7i 7^ £72. From 
Lemma [8] there exists a unique maximal set £7 such that bi > ^*(z,7,£7) for all i G £7. 
Consequently £7i, £72 are subsets of £7 and at least one of them, say £7i a proper subset of £7. 
Then the players in £7 \ ?7i contradict stability (condition 3.). □ 

Proof of Claim M 

(a) Using the definition of 7* we get that 7* U {i} contains all the players who have bidden 
higher than any payment of the mechanism in (&*, b-i). Since 7j is stable at (b*,b-i), each one 
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of these players, who have bidden strictly higher than any payment of the mechanism, should 
be serviced (any value higher than any payment satisfies the definition of CS for Fencing 
Mechanisms), and if they are serviced they obviously have strictly positive utility, and thus 
L* U {i} C Li. 

(b) The idea is to show that for all j G (U* U U) \ L* , bj > C{j,L*, U* U Lj) and since 
we defined U* be the maximal set with this property, we get that Lj C U*. 

From definition of U* we have that for all j eU*\L*, bj > L*,U*)> L*,U*U 
U), where the last inequality follows from Lemma [H 

Now consider some j € Ui \ U* (j ^ i). Since Lj, is stable at (b*,b-i) we get that 
bj > Li,Ui) > L* , U U U*) by applying Lemma [TJ since from (a) L* C Li. 

(c) From (a),(b) and Lemma [1] we have that £*(_7,Lj, Lj) > L* ,U*). As we defined 
Li,U to be the stable pair at (b*,b-i) and j G Lj, for j / i we have bj > £*(j, Lj,Lj) > 

L*,U*) and as j £ L*, we have j G W. □ 

Proof of Claim M 

(a) The pair Li, U is stable at (b*,b-i) (by definition of Li, Ui) but it is not stable at b (from 
our assumption that there exists no stable pair at b). Since the two bid vectors differ only on 
the i-th coordinate we deduce that stability (condition 1. as i G Lj) is not satisfied by the 
i-th coordinate of b, thus bi < £*(i,Lj, U). 

(b) From Claim[8](a) we already have that Lj D L*U{i}. Suppose towards a contradiction 
that Lj = L* U {i}. From Fence Monotonicity (condition (b)) we get that there exists some 
Si, where L* C Si C U* and i G 5j such that for all j G 5j \L* we have Si) = £*(j, Lj, Ui). 

The idea is to show that Lj C Si C Ui, which implies that ^*(i,Lj,C/j) < £(i,S{) = 
£*(i,L*,U*). Then considering also that £*(i,L*,U*) < bi, because i G W, we get Li, U) < 
bi, contradicting the inequality we showed in (a). 

It only remains to show that Lj C S{ C {/j. Notice first that Lj C Si since Lj = L* U {i}. 
Moreover, since for all j G Si \ Li, it holds that bj > £(J, Si) and the bids of these players are 
the same at (b*, b-i), stability of Lj, Ui (condition 3) implies that S% C Ui, because otherwise 
Si \ U 7^ and its elements would violate condition 3. of stability. □ 

Proof of Claim [H 

(a) The pair Lj, U is stable at bid vector (&*, bj,b_^ jj), since Lj, Lj is stable at (bi, b-i) and 
since raising the bid of player j (j G Lj from our initial assumption) to b* does not effect its 
stability. 

(b) From stability of Lj, Lj at (b*, b-i) we get that bj > £*(j, Lj, Li), while from part (a) 
of Claim [9] we get that £*(j,Lj,Uj) > bj. Consequently £*(j,Lj,Uj) > Lj,Lj). 

Supposing towards a contradiction that i G Lj we also get in a similar way as before that 
the pair Lj, Uj is stable at (b*, b*, By Lemma [TT1 these two pairs coincide, which is a 

contradiction because we just showed that the payment of j is different. 

(c) We will show that if there exists some k G Lj \ Li then the mechanism is not GSP at 
inputs, where a stable pair exists. Observe that k ^ i,j. 

Consider first the vector 6 lJ := (b*, b*, 6_{j jy), which stable pair is Lj, Lj from part (a). 
As k ^ Lj either k is not serviced, or if k is serviced, then her utility is zero. As for j she is 
serviced with payment £*(j, Lj, U) < Lj, Uj) = £(j, 0(b*,b-j)) (from (a)). 
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Consider then V := (b*,b-j), where Lj,Uj is stable. As k G Lj and k is serviced and 
b k >£(k,0(b*,b^)). 

Resuming player j strictly prefers 0(6*' J ) to 0{V), while for k the situation is exactly the 
opposite. The idea is to construct a bid vector b' where i has zero utility and either 
or {i,k} is a successful coalition. Let b' = 0(b 1 ^)), 6*, b^jy) and notice that induction 
hypothesis implies that there is a stable pair at b' . Moreover, observe that the three bid 
vectors differ only on the bid of player i and consequently from strategyproofness, at every 
input i is served, she is charged 0{b l,:i )). This implies that if i is served at b' she is charged 
an amount equal to her bid. Moreover, i is serviced at V in the degenerate case where b' = b 3 
as otherwise VP would imply that Oib 3 )) < bj < bj = 0{b 1 ' 3 )). In every case we 
have that i has zero utility in at b' and b 3 . 

Observe first that k must be serviced at b' and charged £(k,0(b')) < O(fc')) as 
otherwise {i, k} would have been able to form a successful coalition when the true values are 
b' bidding V . Similarly we can show that 0(b')) < Oib 1 ' 3 )), excluding the degenerate 
case b' = V , because otherwise {i,j} would have been able to form a successful coalition 
when the true values are b' bidding b 1 ' 3 (the utility of i is kept to zero as in the truthful 
scenario) . 

As a result players j and k strictly prefer 0(b') to 0(b>) and 0(b l ' J ) respectively. If 
i G 0(b') then {i, k} when true utilities are given by b l ' J can form a successful coalition 
bidding b' strictly increasing the utility of k, while keeping the utility of i constant, since she 
is still served with he same payment. If i £ 0(b') then we deduce that {i, j} when the true 
utilities are given by V can form successful coalition bidding b' strictly increasing the utility 
of j, while keeping the utility of i to zero. □ 

C Missing Proofs of Section 7 

Proof of Proposition [T] 

Let L = S \ {i,j} and U = S. 

(a) From condition (a) of Fence Monotonicity, we get that at either S \ {i} or S, every 
player is charged the minimum payment at L, U. Since by our assumption, this is not true 
for S, as S\ {i}) < S), it follows that every other player k G S\{i, k}, £(k, S\ {«}) = 
C(k,L,U) =>Z(k,S\{i}) <£(k,S). 

(b) Notice that j belongs only to S \ {i} and S. Moreover, our assumption implies that 
L, U) = S \ {i}) < S). From condition (b) of Fence Monotonicity, there must be 

a set Si with L C Si C U ', such that i G S and for all k G Si\L, Si) = L, U). By 
our assumption, it is impossible that Si = S and since the only remaining set that contains 
i is S \ {j}, we get that S \ {j}) = (i, L, U) => S \ {j}) < S). 

(c) Let L 1 = S\{j}. Now j is contained only at S, it follows that S) = L' , U) > 
£(j,S \ {i})- Since V \ S \ {i} = {i}, condition (c) of Fence Monotonicity implies that 
e(i,LU{i},U)=C(.i,L,U)=C(i,S)^^i,S)<^i,S\{j}). □ 

Proof of Theorem [3] 

Assume by contradiction that there is a a-budget balanced cost sharing scheme that satisfies 
Fence Monotonicity for C where 1 > a > -. This implies the following relations 
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lc(S)<^{i,S) < C(S). (6) 

Equation [6] (right part) with S = {1,2} and S = {1,3} imply that £(2, {1,2}) < 1 and 
£(3, {1,3}) < 1. We apply Proposition Q] (c) and we get that either f(2, {1,2, 3}) < 1 or 
£(3, {1, 2, 3}) < 1 (or both). W.l.o.g we assume that £(2, {1, 2, 3}) < 1. 

Suppose that £(2, {2, 3}) < 1 £(2, {2, 3}) < £(2, {2}) (Equation [6] (left part) with 
S = {2}: £(2, {2}) > 1). We apply the contra-positive implication of Proposition [T] (b) 
and deduce that £(3, {2, 3}) < £(3, {3}) => £(3, {2, 3}) < x (Equation © (right part) with 
5 = {3}: £(3, {3}) < x)). This contradicts Equation [U] (left hand) with S = {2,3}, since 
£(2,{2,3})+£(3,{2,3})<x + l. 

Suppose that £(2, {2, 3}) > 1 £(2, {2, 3}) > £(2, {1,2, 3}) (from our assumption). No- 
tice that the contra-positive implication of Proposition Q] (a) implies that £(3, {1,2, 3}) < 
£(3, {2, 3}) =>• £(3, {1,2, 3}) < x 2 + x-l (from Equation © (right part) with S = {2,3} it fol- 
lows that £(3, {2, 3}) < x 2 +x — £(2, {2, 3}) <x 2 +x — 1). Using now the contra-positive impli- 
cation ofPropositionQ](b) we get that {1,2, 3}) < {1, 3}) => £(1, {1, 2, 3}) < 1 (Equa- 
tion[6](right part) at S = {1, 3}: £(1, {1, 3}) < 1). This contradicts Equation [6] (left part) with 
5 = {1,2,3}, as f(l,{l,2,3})+f(2,{l,2,3})+f(3, {1,2,3}) < l+l+x 2 +x-l = x 2 +x+l. □ 



D Missing Proofs of Section 8 

Proof of Theorem |4] 

Consider the following process, which takes as input a bid vector b and a set L. 
repeat 

U ^Lu{i e U\L | bi >£*(i,L,U)} 
until For all i G U \ L, b { > C(h L, U) 

We will prove that if we feed this process with the lower set L of the stable pair at b, then 
the outcome is the upper set of the stable pair. 

Obviously by the definition of the process, for its final set U it holds that for all % E U, 
bi > L, U). First, we show that U is the maximal set with this property. 

Assume that there is some U' with U' % U, that satisfies this property, then we have 
that for all i G (U U U') \L, bi > L, U U U'). Thus, it is impossible that the players in 
U U U' are removed at any step of the previous process, contradicting our assumption that 
U 7^ U' U U is the outcome of this process. 

Now consider now the upper set U" of the stable pair at b. Since U" satisfies this property 
it follows that U" C U. Notice that if U" C U ^ 0, then the elements oiU\U" would violate 
stability of L, U" . Thus, U" = U and consequently this process outputs the upper set of the 
stable pair. 

As a result, given an outcome S of a GSP mechanism we can compute L := {i G S \ bi > 
£(i, S)} and use this process to find the upper set U. The time-complexity of this algorithm is 
polynomial in the number of players assuming that we have polynomial-time access to every 
L, U) for all L C U C A and all ieU. □ 
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